yuhr123
V2EX  ›  Docker

Docker Hub 数据库被入侵

  •  
  •   yuhr123 ·
    yuhr123 · Apr 27, 2019 via iPhone · 6962 views
    This topic created in 2576 days ago, the information mentioned may be changed or developed.
    刚刚收到 Docker 支持团队的邮件,告知由于数据库被入侵有 190000 用户账号和密码(已哈希)受影响,财务相关信息未受影响。GitHub 和 bitbucket 的歌曲 token 也被泄漏了,建议尽快修改相关密码。

    On Thursday, April 25th, 2019, we discovered unauthorized access to a single Hub database storing a subset of non-financial user data. Upon discovery, we acted quickly to intervene and secure the site.

    During a brief period of unauthorized access to a Docker Hub database, sensitive data from approximately 190,000 accounts may have been exposed (less than 5% of Hub users). Data includes usernames and hashed passwords for a small percentage of these users, as well as Github and Bitbucket tokens for Docker autobuilds.
    11 replies    2019-04-27 21:18:50 +08:00
    d5
        1
    d5  
       Apr 27, 2019 via iPhone
    这就很难受了
    fanyingmao
        2
    fanyingmao  
       Apr 27, 2019 via Android
    他的哈希希望别是简单的 md5,不然大部分简单密码会被查出。
    SenLief
        3
    SenLief  
       Apr 27, 2019 via Android
    主要是尼玛泄露都用的同一套密码,擦还得全改嘛?
    zhang330700
        4
    zhang330700  
       Apr 27, 2019
    起码还主动公布了...
    lusi1990
        5
    lusi1990  
       Apr 27, 2019 via Android
    回去看看 我有账号不,要不得全改
    maxlino
        6
    maxlino  
       Apr 27, 2019 via iPhone
    还好是 1Password 生成随机密码🌚
    longnight
        7
    longnight  
       Apr 27, 2019 via Android
    应该用了自己的 salt 吧, 所以担心的话只要改 docker 的密码就好
    vencentge
        8
    vencentge  
       Apr 27, 2019 via iPhone
    问题严重的在于 github 上的 token 被拿了,这个就延伸了危害面
    whatsmyip
        9
    whatsmyip  
       Apr 27, 2019
    赶紧删了授权
    watzds
        10
    watzds  
       Apr 27, 2019
    前几天刚注册就这样了。。
    whileFalse
        11
    whileFalse  
       Apr 27, 2019
    我的习惯是不在源代码和构建系统中硬编码任何敏感信息;敏感信息都是在运行时注入。
    About   ·   Help   ·   Advertise   ·   Blog   ·   API   ·   FAQ   ·   Solana   ·   1042 Online   Highest 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 46ms · UTC 23:24 · PVG 07:24 · LAX 16:24 · JFK 19:24
    ♥ Do have faith in what you're doing.